CVE-2005-10004
8.8
HIGH
CVSS 3.1
EPSS 58.0%
Description
Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.
How to fix CVE-2005-10004
To remediate CVE-2005-10004, upgrade the affected package to a fixed version below.
- —upgrade to 0.8.6d-1 or later
Is CVE-2005-10004 being exploited?
Likely — EPSS is 58.0%, placing CVE-2005-10004 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 0.8.6d-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |